CVE-2023-28832: Command Injection
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user input, making it susceptible to command injection. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28832?
CVE-2023-28832 is considered a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2023-28832?
To fix CVE-2023-28832, you should update the affected SIMATIC Cloud Connect devices to the latest version.
Which versions are affected by CVE-2023-28832?
CVE-2023-28832 affects all versions of SIMATIC Cloud Connect 7 CC712 and CC716 that are greater than or equal to V2.0 and less than V2.1.
What is the impact of CVE-2023-28832?
The impact of CVE-2023-28832 includes the potential for an attacker to execute arbitrary commands on the affected devices.
Who is affected by CVE-2023-28832?
Organizations using SIMATIC Cloud Connect 7 CC712 or CC716 with the specified vulnerable firmware versions are affected by CVE-2023-28832.